



























Launch assessments using custom questionnaires built around the research cybersecurity requirements your institution has approved. Department leads, application owners, and vendor contacts contribute responses and supporting evidence. Track completion, deadlines, and reminders across the campaign so reviewers can see which responses still need attention and examine the evidence behind those already submitted.
Maintain connected records for the departments, applications, and vendors included in your research cybersecurity reviews. Record ownership and data classification, then link each record to its assessments, risks, and exceptions. When research leadership asks what was covered, reviewers can identify the assessed units and systems and inspect the results associated with each record.
Publish assessment findings to the risk register with the source question and assessment still connected. Assign an owner, document a remediation plan and milestones, and track progress against the identified gap. Where institutional policy permits an exception, record its justification, compensating controls, and expiration in the exceptions register so the follow-up decision remains documented alongside the affected record.
Generate reports and scorecards from live assessment data to review completion and results across research departments, applications, and vendors. Drill into responses and supporting evidence, then export reports for program reviews. Leadership can examine the underlying assessment record while the security team maintains the findings and follow-up in the same workspace.